Back

MEDIUM

Online Accounts Signon daemon gives out all oauth tokens to any app

Published May 7, 2020

Description

signond before 8.57+15.04.20141127.1-0ubuntu1, as used in Ubuntu Touch, did not properly restrict applications from querying oath tokens due to incorrect checks and the missing installation of the signon-apparmor-extension. An attacker could use this create a malicious click app that collects oauth tokens for other applications, exposing sensitive information.

Affected products

Remediation

No remediation recorded yet.

References (4)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner canonical
Published May 7, 2020
Updated Sep 16, 2024
Reserved Jan 13, 2014

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner canonical
Published May 7, 2020
Updated Sep 16, 2024

GitHub

No data